Skip Links

Network World

  • Social Web 
  • Email 
  • Close

SANS Institute names Top 20 vulnerabilities

By John Fontana , Network World , 10/18/2004
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

The Unix kernel and databases that run on that operating system, along with security sub-systems and instant messaging that run on Windows, are the newest additions to the SANS Institute's annual list of Top 20 vulnerabilities most exploited by hackers.


Core software as security vulnerabilities

The list, released last week, highlights the most common holes exploited in software and is used by the SANS Institute to encourage corporations to make the vulnerabilities a priority as they develop patch-management strategies.

"This is the minimal list that organizations need to get their arms around to protect critical IT infrastructure," says Gerhard Eschelbeck, a member of the committee that developed the list and the CTO at Qualys, a supplier of on-demand vulnerability management. Qualys last week also made available at no cost a Web-based service that will scan infrastructure servers for the Top 20 vulnerabilities.

The federally supported Common Vulnerabilities and Exposures project has catalogued 10,000 vulnerabilities. The SANS Institute says that number includes 3,300 known remotely exploitable vulnerabilities and that 200 of them are linked to the Top 20 identified by SANS.

"If a company searches for all vulnerabilities, they'll find thousands and thousands," says Alan Paller, director of research at the SANS Institute. "If you give a report with 10,000 or 20,000 vulnerabilities to the systems staff, they don't know where to start, and they know they'll never get them all done."

The Top 20 list, which does not rank the vulnerabilities, is actually two lists divided into the Unix and Windows platforms. The vulnerabilities are not necessarily within those operating systems or their variants, but can reside in software that runs on those platforms.

For example, the Windows list calls out Web servers and services, including Microsoft's Internet Information Server, Apache and Sun Java System Web Server.

Eschelbeck says research into the Top 20 does not support arguments that Windows is any more or any less secure than Linux or any other operating system.

"Clearly what is happening now [on any platform] is dealing with the sins of the past, which have been a lack of quality and security in the software development process," he says.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed